F-Secure Quickly Fixes 23 Flaws In Its Anti-Virus Product
Finnish security company F-Secure released patches for its flagship Windows and Linux anti-virus line Thursday to fix flaws revealed by an independent researcher. The bugs in 23 editions of F-Secure Anti-Virus, Internet Gatekeeper, and Internet Security affect how it parses .zip and .rar compressed files, according to the researcher, Thierry Zoller, who works for an unnamed Luxembourg security firm. Maliciously crafted .zip files can be used to create a buffer overflow on PCs defended with F-Secure titles; after that, hackers could load their own code onto the compromised machine. A second flaw can be exploited with specially made .zip or .rar files to hide malicious code from the anti-virus scanning engine, giving users a false sense of security and attackers a way to sneak stuff past protection. More:http://www.informationweek.com/news/showArticle.jhtml?articleID=177102000 |
Comments on "F-Secure Quickly Fixes 23 Flaws In Its Anti-Virus Product"